VYPR

Er7206 Firmware

by TP-Link

CVEs (14)

  • CVE-2025-7851CriOct 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

  • CVE-2025-6542CriOct 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

  • CVE-2025-6541HigOct 21, 2025
    risk 0.57cvss 8.8epss 0.01

    An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.

  • CVE-2025-7850HigOct 21, 2025
    risk 0.47cvss 7.2epss 0.02

    A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

  • CVE-2024-21827HigJun 25, 2024
    risk 0.47cvss 7.2epss 0.01

    A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of…

  • CVE-2023-47618HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.02

    A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2023-47617HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-47209HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-47167HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated…

  • CVE-2023-46683HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can…

  • CVE-2023-43482HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to…

  • CVE-2023-42664HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-36498HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2025-9290MedJan 23, 2026
    risk 0.38cvss 5.9epss 0.00

    An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge…